CVE-2025-13027
8.1Mozilla · Firefox and Thunderbird
Memory safety vulnerabilities in Mozilla Firefox and Thunderbird 144 may allow for memory corruption and potential arbitrary code execution.
Executive summary
Mozilla Firefox and Thunderbird version 144 contain critical memory safety defects that could permit an unauthenticated attacker to achieve arbitrary code execution via memory corruption.
Vulnerability
The software contains multiple memory safety bugs that result in memory corruption. These flaws are reachable by an unauthenticated attacker, who could leverage them to execute arbitrary code on the host system.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, including the loss of data confidentiality, integrity, and availability. With a CVSS score of 8.1, this vulnerability is classified as High, reflecting the significant danger posed by successful exploitation of memory safety flaws in widely used browser and email client applications.
Remediation
Immediate Action: Update all installations of Mozilla Firefox and Mozilla Thunderbird to version 145 or later to apply the necessary security patches.
Proactive Monitoring: Monitor endpoint systems for unexpected application crashes, which may indicate attempted exploitation of memory corruption vulnerabilities.
Compensating Controls: Ensure that systems are running with standard exploit mitigations, such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR), which may complicate exploitation attempts.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists on GitHub.
Analyst recommendation
Given the nature of memory safety bugs and their potential to facilitate arbitrary code execution, this vulnerability represents a significant threat to internal systems. Administrators should prioritize the deployment of version 145 across all workstations to ensure these critical security gaps are closed immediately.
More Mozilla CVEs
Sources
Originally found and disclosed by The Mozilla Fuzzing Team, per the CVE Program record.